Hacker News new | past | comments | ask | show | jobs | submit login

Django has chosen a fine default and for the next several years it's probably unnecessary to second-guess it. Over time, GPU and (more importantly) FPGA-assisted hash cracking may or may not become more common, at which point you'd want to transition to something like scrypt.

You could literally flip a coin to decide between bcrypt and PBKDF2 and it wouldn't matter which side came up.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: